Releases: MetaMask/core
Release list
1314.0.0
@metamask/account-tree-controller 11.0.1
Changed
- Bump
lodash-esfrom^4.17.21to^4.18.1(#10447) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/assets-controllers 112.1.2
Changed
- Bump
@metamask/transaction-controllerfrom^72.0.1to^72.1.0(#10652) - Bump
@metamask/network-controllerfrom^37.0.0to^37.0.1(#10658) - Bump
@metamask/network-enablement-controllerfrom^7.0.1to^7.0.2(#10658) - Bump
@metamask/account-tree-controllerfrom^11.0.0to^11.0.1(#10662) - Bump
@metamask/core-backendfrom^12.0.0to^12.0.1(#10662) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/bridge-controller 82.0.2
Changed
- Bump
@metamask/transaction-controllerfrom^72.0.1to^72.1.0(#10652) - Bump
@metamask/assets-controllerfrom^18.0.0to^18.0.1(#10658) - Bump
@metamask/network-controllerfrom^37.0.0to^37.0.1(#10658) - Bump
@metamask/assets-controllersfrom^112.1.1to^112.1.2(#10662) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/bridge-status-controller 76.3.5
Changed
- Bump
@metamask/bridge-controllerfrom^82.0.0to^82.0.2(#10648, #10662) - Bump
@metamask/transaction-controllerfrom^72.0.1to^72.1.0(#10652) - Bump
@metamask/network-controllerfrom^37.0.0to^37.0.1(#10658) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/claims-controller 1.0.3
Changed
- Bump
@metamask/base-data-servicefrom^2.0.0to^2.1.0(#10502) - Bump
@tanstack/query-corefrom^5.89.0to^5.103.2(#10511) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/core-backend 12.0.1
Changed
- Bump
@metamask/account-tree-controllerfrom^11.0.0to^11.0.1(#10662) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/kyc-controller 0.6.1
Changed
- Bump
@metamask/base-data-servicefrom^2.0.0to^2.1.0(#10502) - Bump
@tanstack/query-corefrom^5.89.0to^5.103.2(#10511) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/notification-services-controller 29.0.3
Changed
- Bump
lodash-esfrom^4.17.21to^4.18.1(#10447) - Bump
firebasefrom^11.2.0to^11.10.0(#10530) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/profile-controller 1.0.1
Changed
- Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/profile-metrics-controller 5.1.3
Changed
- Bump
@metamask/transaction-controllerfrom^72.0.0to^72.1.0(#10462, #10652) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/profile-sync-controller 34.0.0
Changed
- Open the verification session on enrollment and let the server set its lifetime (#10653)
completeCredentialEnrollmentopens a verification session with the assertionPOST /api/v2/mfa/enroll/completereturns for the new credential, replacing any earlier one, so no separate verification is needed right after enrolling. If the token exchange fails, the enrollment still succeeds and the earlier session is keptSRPJwtBearerAuth.completeMfaEnrollmentandJwtBearerAuth.completeMfaEnrollmentreturn that assertion- The session lasts for the token's
expires_in, measured on the device clock, instead of at most 15 minutes
- Replace JS AES implementation with
@metamask/cryptography(#10621) - Bump
immerfrom^9.0.21to^11.1.18(#10382)
Removed
- BREAKING: Remove
VERIFICATION_SESSION_TTL_MS, as the server now sets the verification session lifetime (#10653)
Fixed
- Coalesce overlapping
performSignIncalls so only one sign-in runs at a time (#10646) - Rely on
@metamask/key-treecrypto implementation for HMAC-SHA-512 instead of hardcodednobleimplementation (#10424)@metamask/key-treeuses WebCrypto API if available and fallback tonobleotherwise.- One note, we expect the platform to provide a fully-compliant WebCrypto (
crypto.subtle) implementation for this to work (@metamask/key-treedetection is global and not "per crypto functions").
@metamask/ramps-controller 26.2.0
Changed
RampsController.setSelectedTokenmatcheseip155ERC-20 asset ids case-insensitively and keeps the catalog token's ownassetId. Non-EVM asset ids still require an exact match (#10545)- Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/shield-controller 7.0.4
Changed
- Bump
@metamask/transaction-controllerfrom^72.0.0to^72.1.0(#10462, #10652) - Bump
@metamask/base-data-servicefrom^2.0.0to^2.1.0(#10502) - Bump
@tanstack/query-corefrom^5.89.0to^5.103.2(#10511) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/smart-transactions-controller 27.1.0
Changed
- Expose structured fetch error data (#10494)
- Export
getErrorDatautil to parse Sentinel API errors (#10642) - Bump
@metamask/transaction-controllerfrom^72.0.0to^72.1.0(#10462, #10652) - Bump
@ethersproject/bytesfrom^5.7.0to^5.8.0(#10480) - Bump
lodash-esfrom^4.17.21to^4.18.1(#10447) - Bump
@ethersproject/transactionsfrom^5.7.0to^5.8.0(#10483) - Bump
@metamask/network-controllerfrom^37.0.0to^37.0.1(#10658) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/social-controllers 3.6.0
Added
- Add
block,fetchBlockedProfiles, andfetchBlockedContentmethods toSocialService(and the matchingSocialService:block,SocialService:fetchBlockedProfiles, andSocialService:fetchBlockedContentmessenger actions) for the social-api moderation block endpoints (#10656)blockcallsPUT /moderation/blockwith exactly one ofprofileId,commentId, orreplyId, plus an optionalreason. The endpoint returns 204.fetchBlockedProfilescallsGET /moderation/blocks/profilesand returns traders the caller has blocked, most recently blocked first. Passcursorfrom the previous page;cursorisnullon the last page.fetchBlockedContentcallsGET /moderation/blocks/contentand returns comments and replies the caller has blocked, most recently blocked first, with the same cursor pagination.
Changed
- Bump
@metamask/core-backendfrom^12.0.0to^12.0.1(#10662) - Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
@metamask/subscription-controller 12.0.1
Changed
- Bump
@metamask/profile-sync-controllerfrom^33.0.0to^34.0.0(#10662)
1313.0.0
@metamask/analytics-controller 4.0.0
Changed
- BREAKING:
AnalyticsControllerMessengerrequiresConfigRegistryController:getStatein its allowed actions andConfigRegistryController:stateChangedin its allowed events (#10448) - Update
AnalyticsController.initto listen for ConfigRegistryController state changes and update in-memory event-purpose classification when the version differs (#10448) - Add
@metamask/config-registry-controller^4.0.0as a dependency (#10448) - Bump
lodash-esfrom^4.17.21to^4.18.1(#10447) - Bump
@metamask/config-registry-controllerfrom^4.0.0to^5.0.0(#10658)
@metamask/assets-controller 18.0.1
Changed
- Bump
@metamask/transaction-controllerfrom^72.0.1to^72.1.0(#10652) - Bump
@metamask/config-registry-controllerfrom^4.0.0to^5.0.0(#10658) - Bump
@metamask/network-controllerfrom^37.0.0to^37.0.1(#10658) - Bump
@metamask/network-enablement-controllerfrom^7.0.1to^7.0.2(#10658)
@metamask/config-registry-controller 5.0.0
Added
- Add
ConfigRegistryApiService.fetchEventsConfig, which hits/v1/config/events-config(#10448)
Changed
- BREAKING:
ConfigRegistryControllerMessengerrequiresConfigRegistryApiService:fetchEventsConfigin its allowed actions (#10448) ConfigRegistryControllernow caches the result from/v1/config/events-configinconfigs.eventsConfigin its polling loop (#10448)- Bump
@metamask/utilsfrom^11.12.0to^12.0.0(#10192) - Bump
@metamask/keyring-controllerfrom^28.0.0to^28.1.0(#10418)
@metamask/network-controller 37.0.1
Changed
- Bump
uuidfrom^8.3.2to^11.1.1(#10117, #10243) - Bump
@metamask/utilsfrom^11.12.0to^12.0.0(#10192) - Bump
immerfrom^9.0.6to^11.1.18(#10331, #10382) - Bump
@metamask/analytics-controllerfrom^3.0.0to^4.0.0(#10301, #10411, #10658) - Bump
@metamask/config-registry-controllerfrom^4.0.0to^5.0.0(#10658)
@metamask/network-enablement-controller 7.0.2
Changed
- Bump
@metamask/transaction-controllerfrom^72.0.0to^72.1.0(#10462, #10652) - Bump
@metamask/config-registry-controllerfrom^4.0.0to^5.0.0(#10658) - Bump
@metamask/network-controllerfrom^37.0.0to^37.0.1(#10658)
@metamask/wallet 16.0.1
Changed
1312.0.0
@metamask/subscription-controller 12.0.0
Added
- BREAKING: Add
SubscriptionController:isUserEligibleForTrialto report whether a user can start a trial for a product (#10622)- Clients must grant
SubscriptionControllerMessengeraccess toSeedlessOnboardingController:getIsUserAuthenticatedin order to callSubscriptionController:isUserEligibleForTrial.
- Clients must grant
Changed
- Bump
@metamask/money-account-balance-servicefrom^3.1.1to^3.1.2(#10624) - Bump
@metamask/chomp-api-servicefrom^6.0.0to^6.0.1(#10626) - Bump
@metamask/transaction-controllerfrom^72.0.1to^72.1.0(#10652)
@metamask/wallet 16.0.0
Changed
- BREAKING: Grant
SubscriptionControlleraccess toSeedlessOnboardingController:getIsUserAuthenticated(#10622)- Clients must delegate this action to the Wallet messenger.
- BREAKING: Wire up
ConfigRegistryApiService:fetchEventsConfigaction handler inconfigRegistryControllerinitialization (#10448)- The messenger passed to Wallet must support this action.
- Bump
@metamask/transaction-controllerfrom^72.0.1to^72.1.0(#10652) - Bump
@metamask/subscription-controllerfrom^11.0.0to^12.0.0(#10655)
1311.0.0
@metamask/cryptography 1.1.0
Added
- Add an
additionalDataoption to AES-GCMencryptanddecrypt(#10628) - Allow HKDF functions to derive from an empty input when
unsafeInputKeyingMaterialis set (#10628)
Fixed
- Narrow return type for AES
encryptfunction toUint8Array<ArrayBuffer>(#10623)
@metamask/transaction-controller 72.1.0
Changed
-
Include a
RedeemerEnforcercaveat in EIP-7702 gas fee token simulations viasuggestFees.withRedeemerEnforcer(#10615) -
Bump
ethereum-cryptographyfrom^2.1.2to^2.2.1(#10485) -
Bump
lodash-esfrom^4.17.21to^4.18.1(#10447) -
Bump
@ethersproject/walletfrom^5.7.0to^5.8.0(#10484) -
Bump
@metamask/core-backendfrom^11.0.0to^12.0.0(#10648)
1310.0.0
@metamask/assets-controller 18.0.0
Added
- BREAKING:
AssetsControllerMessengernow requires theMultichainTransactionsControllerTransactionConfirmedEventallowed event (#10585)AssetsControllersubscribes toMultichainTransactionsController:transactionConfirmedso non-EVM (Snap keyring) transactions trigger the same post-transaction balance refresh as EVMTransactionController:transactionConfirmed.- Consumers must delegate
MultichainTransactionsController:transactionConfirmedonto the Assets controller messenger. Without that delegation the subscription is registered and never fires.
Changed
- Bump
lodash-esfrom^4.17.21to^4.18.1(#10447) - Bump
@ethersproject/providersfrom^5.7.0to^5.8.0(#10482) - Bump
@metamask/assets-controllersfrom^112.0.4to^112.1.1(#10633, #10648) - Bump
@metamask/phishing-controllerfrom^18.1.1to^18.2.0(#10633) - Bump
@metamask/core-backendfrom^11.0.0to^12.0.0(#10648)
Fixed
- Fix
PriceDataSourcesupported-network filtering so it reads the object-shapedpartialSupportreturned by the Price API/v2/supportedNetworksendpoint (#10582) - On the v5 balance path, stop seeding every enabled chain's native onto an account when the update arrives after that account is no longer selected (#10567)
- On unlock, drop stored balances whose chain namespace is outside the selected account's scopes (#10567)
@metamask/assets-controllers 112.1.1
Changed
- Bump
@metamask/core-backendfrom^11.0.0to^12.0.0(#10648)
@metamask/bridge-controller 82.0.1
Changed
- Bump
@metamask/assets-controllerfrom^17.0.0to^18.0.0(#10648) - Bump
@metamask/assets-controllersfrom^112.1.0to^112.1.1(#10648)
@metamask/client-utils 3.0.4
Changed
- Bump
eth-chainlistfrom^0.0.795to^0.0.844(#10438, #10524) - Bump
@metamask/transaction-controllerfrom^72.0.0to^72.0.1(#10462) - Bump
@metamask/core-backendfrom^11.0.0to^12.0.0(#10648)
@metamask/core-backend 12.0.0
Changed
- BREAKING:
PriceSupportedNetworksResponsenow matches the real/v2/supportedNetworksresponse, withpartialSupporttyped as{ spotPricesV2: string[]; spotPricesV3: string[] }instead ofstring[](#10582) - Bump
uuidfrom^9.0.1to^11.1.1(#10243) - Bump
@metamask/profile-sync-controllerfrom^32.1.1to^33.0.0(#10348, #10409, #10418, #10459) - Bump
@tanstack/query-corefrom^5.62.16to^5.103.2(#9324, #10511) - Bump
@metamask/keyring-controllerfrom^28.0.0to^28.1.0(#10418) - Bump
cockatielfrom^3.1.2to^3.2.1(#10436) - Bump
@metamask/account-tree-controllerfrom^10.0.1to^11.0.0(#10459)
Deprecated
- Deprecate
PriceSupportedNetworksResponsein favor ofPriceV2SupportedNetworksResponse(#10582)
@metamask/social-controllers 3.5.0
Added
- Add
SocialRealtimeServicefor subscribing to Social realtime feed events through the shared backend WebSocket connection (#10561)
Changed
- Bump
@metamask/base-data-servicefrom^2.0.0to^2.1.0(#10502) - Bump
@metamask/core-backendfrom^11.0.0to^12.0.0(#10648)
@metamask/transaction-pay-controller 30.0.1
Changed
1309.0.0
1308.0.0
@metamask/profile-controller 1.0.0
Added
- Add
ProfileControllerfor managing user profile state, exposinggetMetaMaskProfile,getXprofile,createProfile,replaceProfile,updateProfile,deleteProfile,checkUsernameAvailability,getXAuthUrl,connectX, andgetXAccountvia the messenger (#10558) - Add
ProfileServicefor communicating with the MetaMask Profile API, exposinggetProfile,createProfile,replaceProfile,updateProfile,deleteProfile,checkUsernameAvailability,getXAuthUrl,connectX, andgetXAccountvia the messenger, with superstruct validation on all inputs and responses (#10558)
1307.0.0
@metamask/assets-controllers 112.1.0
Added
- Add optional
securityDataproperty toRwaToken, populated whenincludeTokenSecurityDatais requested (#10542) - Add optional
includeTokenSecurityDataproperty toFetchRwasParams(#10542)
Changed
-
Bump
immerfrom^9.0.21to^11.1.18(#10382) -
Bump
@metamask/transaction-controllerfrom^72.0.0to^72.0.1(#10462) -
Bump
@ethersproject/bignumberfrom^5.7.0to^5.8.0(#10479) -
Bump
lodash-esfrom^4.17.21to^4.18.1(#10447) -
Bump
@ethersproject/providersfrom^5.7.0to^5.8.0(#10482) -
Bump
@ethersproject/addressfrom^5.7.0to^5.8.0(#10478) -
Bump
@tanstack/query-corefrom^5.89.0to^5.103.2(#10511) -
NftControllernow attributes itsPhishingController:bulkScanUrlscalls to thenft-detectionrequest source, so NFT metadata URL scans are distinguishable from other callers in phishing-detection service metrics (#10357) -
Bump
@metamask/phishing-controllerfrom^18.1.1to^18.2.0(#10633)
@metamask/phishing-controller 18.2.0
Added
- Add optional request-source attribution parameters to
PhishingController.scanUrlandbulkScanUrls, emitting anx-request-sourceheader. (#10357)
Changed
1306.0.0
@metamask/chomp-api-service 6.0.1
Changed
- Bump
@tanstack/query-corefrom^5.89.0to^5.103.2(#10511)
Fixed
- Ignore unrecognised intent types returned by the CHOMP API instead of failing to parse the whole response (#10609)
getIntentsByAddressnow omits intents whosemetadata.typeis not a knownChompIntentType.getServiceDetailsnow omits unknown values from each protocol'sintentTypes.
1305.0.0
@metamask/money-account-balance-service 3.1.2
Fixed
- Stop including balance amounts in
MoneyAccountBalanceValidationErrormessages, which are reported via the messenger'scaptureException(#10619)